[Freedombox-discuss] identicons are not strong crypto [was: Re: Tap-to-share PGP key exchange]
- Subject: [Freedombox-discuss] identicons are not strong crypto [was: Re: Tap-to-share PGP key exchange]
- From: drwho@virtadpt.net (The Doctor)
- Date: Mon, 03 Oct 2011 13:13:46 -0400
- Message-id: <[🔎] 4E89ED4A.8020108@virtadpt.net>
- In-reply-to: <4E85EB8B.3090808@fifthhorseman.net>
- References: <1316794602.19150.140258146975101@webmail.messagingengine.com> <CAGDjS3d+S3VOnWzH5fWK3qiBWfF4e=qzTXe3EGOdmtG89TDP4Q@mail.gmail.com> <21AF649B-05E1-48AE-B4F8-2F84FB7E33E7@let.de> <87hb426axz.fsf@debian.home> <B57606A6-73D8-4A32-ADCB-36F0E08072E8@let.de> <8762ki69vx.fsf@debian.home> <20110925155424.GR25711@leitl.org> <20110926070306.2349b14c.weaver@riseup.net> <4E80D173.7020907@googlemail.com> <4E8482E9.40109@googlemail.com> <4E849282.4010401@fifthhorseman.net> <4E85AC0A.9020808@googlemail.com> <1317390628.14509.2.camel@blacksword.home> <4E85CDB1.7000305@googlemail.com> <4E85D574.2000504@fifthhorseman.net> <4E85D9FF.30909@googlemail.com> <263ECD56-31B9-4396-AD5D-9B3F99F76D40@prol.etari.at> <4E85EB8B.3090808@fifthhorseman.net>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
On 09/30/2011 12:17 PM, Daniel Kahn Gillmor wrote:
> I have yet to see any analysis showing that an attacker couldn't
> coerce the digested data to create an identicon that most normal
> humans would consider to be a "match".
Sort of like this?
http://www.thc.org/papers/ffp.html
I am surprised that no one has brought up bubble-babble fingerprints
yet (https://secure.wikimedia.org/wikipedia/en/wiki/Bubble_Babble) or
a randomart depiction
(http://superuser.com/questions/22535/what-is-randomart-produced-by-ssh-keygen).
- --
The Doctor [412/724/301/703]
PGP: 0x807B17C1 / 7960 1CDC 85C9 0B63 8D9F DD89 3BD8 FF2B 807B 17C1
WWW: https://drwho.virtadpt.net/
"Perpugilliam Brown to airlock three, Perpugilliam Brown to airlock
three.."
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/
iEYEARECAAYFAk6J7UoACgkQO9j/K4B7F8FJWQCdHCKQxnLJuiCfWNSG+5ppv6jw
ZsYAn128LIlbwU+smfJ6A9WcaQ3DYrPK
=brKR
-----END PGP SIGNATURE-----
Reply to: